Weaknesses of type CWE-601

1,188 results

Redirecionamento aberto para site não confiável

É quando uma aplicação redireciona o usuário para uma URL fornecida por ele (ou por um atacante) sem validação prévia. O navegador segue o redirecionamento automaticamente, levando a vítima para um site malicioso que pode clonar a interface legítima para roubar credenciais ou distribuir malware, com aparência de vir de um domínio confiável.

Example

Um link do tipo `https://banco.com/redirect?url=https://banco-falso.com` recebe a URL de destino como parâmetro e redireciona direto sem checagem. Atacante envia `https://banco.com/redirect?url=https://phishing.com` em email, e a vítima clica pensando estar acessando o banco.

How to mitigate

Valide sempre a URL de destino contra uma lista branca de domínios permitidos ou use URLs relativas. Se aceitar redirecionamentos dinâmicos, verifique que o host pertence ao seu domínio ou a uma lista explícita de parceiros confiáveis.

CVE-2024-8527HIGHALC WebCTRL Carrier i-Vu Open Redirect via URL parameterEPSS 0.2%CVE-2025-66596MEDIUMA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properly validate request hEPSS 0.2%CVE-2025-55032MEDIUMFocus incorrectly ignores Content-Disposition headers for some MIME typesEPSS 0.2%CVE-2026-62517MEDIUMVulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions tEPSS 0.2%CVE-2026-2376MEDIUMMirror-registry: quay: quay: server-side request forgery via open redirect vulnerability in web interfaceEPSS 0.2%CVE-2026-60642HIGHVulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are EPSS 0.2%CVE-2025-62690LOWOpen redirect in error page when link opened in new tabEPSS 0.1%CVE-2026-10856MEDIUMOpen redirect in MISP dashboard button widget URL handlingEPSS 0.1%CVE-2025-2068MEDIUMAn open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a locEPSS 0.1%CVE-2024-58342MEDIUMXenForo Open Redirect via getDynamicRedirectEPSS 0.1%CVE-2025-32748MEDIUMDell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remoEPSS 0.1%CVE-2026-18505MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.1%CVE-2026-21826MEDIUMHCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injectionEPSS 0.1%CVE-2026-34083MEDIUMsignalk-server: OAuth Authorization Code Theft via Unvalidated Host Header in OIDC FlowEPSS 0.1%CVE-2025-27900MEDIUMMultiple vulnerabilities in IBM Java SDK affecting Db2 Recovery Expert for Linux, Unix and WindowsEPSS 0.1%CVE-2026-80444MEDIUMUnauthenticated Open Redirect Vulnerability in Abis Technology's AVESİSEPSS 0.1%CVE-2024-13983MEDIUMInappropriate implementation in Lens in Google Chrome on iOS prior to 136.0.7103.59 allowed a remote attacker to perform UI spoofing via a cEPSS 0.1%CVE-2026-60685MEDIUMVulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affecEPSS 0.1%CVE-2026-60842MEDIUMVulnerability in the Oracle Knowledge Management product of Oracle E-Business Suite (component: Search). Supported versions that are affectEPSS 0.1%CVE-2026-62563MEDIUMVulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that arEPSS 0.1%